ARTICLE
11 April 2023

HHS Releases Cybersecurity Guide

SM
Sheppard Mullin Richter & Hampton

Contributor

Sheppard Mullin is a full service Global 100 firm with over 1,000 attorneys in 16 offices located in the United States, Europe and Asia. Since 1927, companies have turned to Sheppard Mullin to handle corporate and technology matters, high stakes litigation and complex financial transactions. In the US, the firm’s clients include more than half of the Fortune 100.
The US Department of Health and Human Services recently updated its guide to help the private and public healthcare sectors develop cybersecurity protocols that address NIST's Framework for Improving...
United States Privacy

The US Department of Health and Human Services recently updated its guide to help the private and public healthcare sectors develop cybersecurity protocols that address NIST's Framework for Improving Critical Infrastructure Cybersecurity. The guide is a toolkit, with information and resources intended to help companies implement cybersecurity programs in the health care space. While the aim of this guidance is to help companies implement NIST's protocols for protecting US critical infrastructure, the recommendations contained in the guide mirror other agencies' security recommendations (for example those we have written about from the Department of Labor and the FDA).

Included in the guide are recommendations on implementing NIST's seven-step cybersecurity framework (prioritize – orient – create a current profile – risk assessment – target profile – gap identification – action plan). Within the guide are items specific to health care providers, including conduct an enterprise wide inventory of the creation, reception, maintenance, and transmission of electronic protected health information (ePHI) and doing a business impact analysis on systems that create, receive, maintain, and transmit ePHI. The guide also contains information about external resources available to assist in cybersecurity efforts (with a list of many tools developed for the health care industry, like the Health Care and Public Health Risk Identification and Site Criticality Toolkit).

Putting it into practice: While this guide is intended as a resource rather than a compliance roadmap, it is a reminder that HHS is increasing its focus on cybersecurity.

The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.

Mondaq uses cookies on this website. By using our website you agree to our use of cookies as set out in our Privacy Policy.

Learn More